RMM
Jamf Pro integration
Reads Mac device posture per Jamf Site — macOS end-of-life, EDR agent presence, boot-drive free space. Read-only API Role.
Setup steps are for connected customers — sign in to read them.
What we find in Jamf Pro
Mac fleet: OS end-of-life by macOS version, EDR agent presence, boot-drive free space — read per Jamf Site, so an MSP running one Jamf Pro instance across many customers is covered exactly like Addigy. Patch compliance and hardware age not yet wired (separate endpoints, unconfirmed response schemas).
Every finding lands on your Client Upsell board as a named client with a number beside it — not a report you have to read.
What the Jamf Pro connection does
Read — powers Client Upsell
Read your clients' stack
Device posture: patch state, EDR, OS and hardware age, software EOL.
Read-only, and checked
A write-capable credential is refused, not warned about
We test the key you give us the moment you submit it. If it can write to Jamf Pro, we reject it and tell you which step to change — there is no override. It is encrypted at rest, held in one vault in one application, and nothing is ever written back to Jamf Pro.
Jamf Pro integration — common questions
- What does the Jamf Pro integration read?
- Reads Mac device posture per Jamf Site — macOS end-of-life, EDR agent presence, boot-drive free space. Read-only API Role.
- What does MSProspector find in Jamf Pro?
- Mac fleet: OS end-of-life by macOS version, EDR agent presence, boot-drive free space — read per Jamf Site, so an MSP running one Jamf Pro instance across many customers is covered exactly like Addigy. Patch compliance and hardware age not yet wired (separate endpoints, unconfirmed response schemas).
- Is the Jamf Pro connection read-only?
- Yes. The credential is checked live when you submit it and a write-capable one is refused, with no override — and every connector we ship is checked, at every commit, by an automated build rule that fails if it contains anything other than a GET call. The credential itself is wrapped by a key that lives in Azure Key Vault's hardware security module and never leaves it — our application can ask the vault to wrap or unwrap it, but cannot read the wrapping key. See our security page for the full picture.
